VYPR
Unrated severityOSV Advisory· Published Mar 30, 2019· Updated Aug 4, 2024

CVE-2019-10646

CVE-2019-10646

Description

Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded.

Affected products

2
  • Wolfcms/WolfCMSOSV2 versions
    0.7.0, 0.7.1, 0.7.2, …+ 1 more
    • (no CPE)range: 0.7.0, 0.7.1, 0.7.2, …
    • (no CPE)range: =0.8.3.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.